PT-2025-48380 · Tryton · Tryton

Published

2025-11-27

·

Updated

2025-12-05

·

CVE-2025-66423

CVSS v3.1

7.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions Tryton versions prior to 6.0.70 Tryton versions prior to 7.0.40 Tryton versions prior to 7.4.21 Tryton versions prior to 7.6.11
Description The software does not enforce access rights for the route of the HTML editor.
Recommendations Update to Tryton version 6.0.70 or later. Update to Tryton version 7.0.40 or later. Update to Tryton version 7.4.21 or later. Update to Tryton version 7.6.11 or later.

Fix

Incorrect Authorization

Weakness Enumeration

Related Identifiers

CVE-2025-66423
DSA-6064-1
GHSA-P3P5-XRMV-4J6X

Affected Products

Tryton